Alerting: Cayosoft Guardian built-in alerting rules
This article provides a list of built-in alerting rules available in Cayosoft Guardian.
Enable, disable, or modify built-in rules
To enable, disable, or modify built-in alerting rules:
- Open the Cayosoft Guardian web portal.
- Expand the Change Monitoring node.
- Click the Change Alerting Rules node.
- To view or edit a rule, select the rule, and then click Properties.
Built-in alerting rules
| Rule name | Scope | Severity | Threat description | Rule description and additional information |
|---|---|---|---|---|
| AD privileged group membership changed | Active Directory | High | Privileged groups in Active Directory are groups granted powerful rights, privileges, and permissions that allow near-complete control over Active Directory and domain-joined systems. Adding a new account to such a group can introduce significant risk. | Raises an alert when a member is added to a privileged group in the Active Directory domain. Examples of privileged groups include Administrators, Backup Operators, Server Operators, ADSyncAdmins, DnsAdmins, Domain Admins, Enterprise Admins, and Schema Admins. The alert identifies the target group and the member or members added. |
| Entra Global Administrator role membership changed | Microsoft Entra ID | High | A Global Administrator can manage all aspects of Microsoft Entra ID and any Microsoft services that use Entra identities. Adding a new account to such a powerful role can introduce significant risk. | Raises an alert when a member is added to the Global Administrator, also known as Company Administrator, role in the Entra tenant. The alert includes both eligible and active assignments. |
| Conditional Access policy is modified or deleted | Microsoft Entra ID | Medium | Conditional Access policies enforce critical access controls such as multi-factor authentication and device compliance. Modifying or deleting a policy can weaken the organization's security posture and open an attack path. | Raises an alert when a Conditional Access policy is modified or deleted in the Entra tenant. The alert identifies the affected policy and the change type. |
| New Guest user created | Microsoft Entra ID | Informational | With External Identities, formerly known as Guests, people outside your organization can access apps and resources while signing in with their own identity. Depending on tenant settings, member users can invite guests, who may then gain access to sensitive data. | Raises an alert each time a new guest user is invited to the tenant. The alert identifies the invited guest and the tenant. |
| Guest user added to group | Microsoft Entra ID | Medium | Some groups have access to sensitive data, so it is important to monitor when guest accounts are added to a group. | Raises an alert when a guest user, also known as an invited external identity, is added to a group in Entra ID. The alert identifies the target group. |
| Guest permissions settings changed for team | Microsoft Teams | Informational | Depending on a team's settings, guest users may gain access to sensitive data. Changes to guest permissions should be monitored. | Raises an alert when guest permission settings are changed for a specific team. This rule is shipped disabled by default and must be enabled to take effect. |
| Send As permission assigned for Exchange mailbox | Exchange Online | Informational | In Exchange Online, delegating the Send As permission lets another user send messages that appear to come from the mailbox. Such delegation can expose sensitive data or enable impersonation. | Raises an alert when the Send As permission is assigned on an Exchange Online mailbox. The alert identifies the mailbox and the trustee granted the permission. |
| Send On Behalf permission assigned for Exchange mailbox | Exchange Online | Informational | Delegating the Send On Behalf permission lets another user send messages on behalf of the mailbox. Such delegation can expose sensitive data or be abused. | Raises an alert when the Send On Behalf permission is assigned on an Exchange Online mailbox. The alert identifies the mailbox and the trustee granted the permission. |
Comments
0 comments
Please sign in to leave a comment.